Privacy Policy
Effective date: September 28, 2026
This Privacy Policy explains how Islington Partners LTD (“Calendr”, “we”, “us”, or “our”) collects, uses, and protects personal information through the Calendr service at calendr.so and related domains.
1. Who we are
Calendr is operated by Islington Partners LTD, a company registered in England and Wales (company number 08606033).
We are registered with the UK Information Commissioner’s Office (registration number ZA726799).
Privacy contact: thegoodpeople@calendr.so
Registered address: Friarswood, Chipperfield Road, Kings Langley, Hertfordshire, England, WD4 9JB
2. Roles under UK GDPR
Calendr usually acts as a controller for personal data relating to:
- Account administration, authentication, and team access
- Subscription billing and payment administration
- Service operation, support, fraud prevention, and security
- First-party product analytics (for example operational usage on the platform)
- Website analytics and marketing measurement on calendr.so, where you have consented
Calendr acts as a processor when we process booking, contact, CRM, form-response, and integration-related personal data on behalf of a subscribing firm that uses Calendr to serve its clients and contacts.
In those cases, the subscribing firm is normally the controller of that client and contact data and decides why and how it is used.
3. Information we collect
3.1 Account and firm information
- Name, email address, and organisation or firm name
- Password (stored as a secure one-way hash, not as readable text)
- Role, preferences, and team membership
3.2 Booking and client data (processor data)
- Invitee and attendee contact details, meeting times, and booking history
- Custom booking and qualifying form responses
- CRM-style people, organisations, and contact records created by the firm
- Calendar availability and connected calendar metadata where integrations are enabled
3.3 Technical and usage data
- IP address, browser type, device information, and server logs
- Pages viewed and actions taken on our website and in the application
- Cookie and similar technology data (see our Cookies Policy)
4. How we use information
- Provide, maintain, secure, and improve the service
- Process subscriptions and payments
- Send transactional messages such as confirmations and reminders
- Support customers and investigate issues
- Comply with legal obligations and enforce our terms
- Measure website performance and advertising effectiveness where you have consented to optional cookies
5. Legal bases (UK GDPR)
We rely on contractual necessity, legitimate interests, consent (where required), and legal obligation, depending on the processing activity. Optional website analytics and marketing cookies are used only with your consent under PECR and UK GDPR.
6. Hosting, storage, and security
Hosting. Render hosts the Calendr application and our primary PostgreSQL databases. Each firm’s database is stored in a region aligned with the firm’s configured data region (UK, EU, or US). Our deployment configuration uses Render database regions of London (UK), Frankfurt (EU), and Ohio (US).
Files. Amazon Web Services (AWS) S3 is used for relevant file and object storage. Configured S3 regions are UK (eu-west-2), EU (eu-central-1), and US (us-east-1), according to the firm’s region.
Email. Amazon SES is used for transactional email delivery. SES is not a region-specific customer database.
Some supporting services may process data in other countries. Processing does not always remain exclusively in the customer’s selected region.
We use HTTPS/TLS for data in transit, provider-managed encryption at rest for databases and object storage, access controls, and additional application-level protection for sensitive credentials (such as OAuth tokens). We do not claim absolute security, and Calendr itself does not currently hold ISO 27001, SOC 2, or similar certification unless separately documented in writing.
7. Recipients and subprocessors
We use service providers that process personal data on our instructions or on yours, including:
- Render — application and database hosting
- Amazon Web Services — S3 object storage and SES transactional email
- Stripe — subscription and payment administration
- Google and Microsoft — authentication, calendar, and related services when connected by a customer
- Customer-enabled integrations such as Karbon or Notion when a firm turns them on and uses them
- Google Analytics and Meta (Facebook) Pixel — website analytics and marketing on calendr.so, only with consent
No data is sent to an optional integration unless the customer enables or uses that integration. Google Analytics and Meta Pixel are not loaded on public client booking pages.
We do not sell personal data.
8. International transfers
Where personal data is transferred outside the UK or EEA, we rely on an applicable UK adequacy decision where one exists. Where adequacy does not apply, we use appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where appropriate.
9. Retention and deletion
Account deletion. When an authorised firm administrator deletes the firm account in Calendr, production customer data for that firm is deleted promptly from our live systems. Residual copies may remain in Render database backups for up to seven days before being overwritten or expiring.
Subscription cancellation. Cancelling a subscription is not the same as deleting the firm account and does not necessarily trigger immediate deletion.
Ordinary termination. If a customer stops using the service without an immediate account-deletion action, our internal process aims to delete or anonymise customer data within 60 days, unless a longer period is required by law or agreed in writing.
Legal and operational records. We may retain limited billing, fraud-prevention, security, or audit records where legally required or necessary to establish, exercise, or defend legal claims.
Automated retention (when scheduled jobs are enabled). First-party website visit/event analytics (Ahoy) may be deleted after approximately 13 months. Invitee personal data on very old cancelled bookings may be anonymised after approximately seven years. These automated rules depend on background jobs being enabled in the environment.
10. Prohibited data
Customers must not intentionally submit special-category personal data under Article 9 UK GDPR, criminal-conviction data, or personal data relating to children under 16 through Calendr unless we agree in writing and appropriate safeguards are documented.
11. Your rights and complaints
Under UK GDPR you may have rights to access, rectify, erase, restrict, object, and data portability, and to withdraw consent where processing is based on consent. We aim to respond within one month.
Calendr account holders
Download account data from Profile settings or submit a verified request at calendr.so/dsar.
Booking invitees and CRM contacts
If a Calendr customer invited you to book or added you as a contact, that customer is normally the controller. Contact them first, or use calendr.so/dsar with their booking subdomain.
You may complain to the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint/. We encourage you to contact us first at thegoodpeople@calendr.so.
12. Cookies and similar technologies
See our Cookies Policy.
On the calendr.so marketing site you can change optional cookie choices using Cookie settings in the page footer.
13. Children
Calendr is not intended for children under 16 and must not be used to collect their personal data except as permitted by law and our written agreement.
14. Changes
We may update this policy from time to time. We will post the revised version here with an updated effective date and, where appropriate, notify account holders.
15. Contact
Islington Partners LTD (company number 08606033, ICO registration ZA726799)
Email: thegoodpeople@calendr.so